# Can one download a virus from an MP3 or WAV file?

**URL:** <https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344>\
**Category:** Factual Questions\
**Created:** [May 29, 2003, 7:44pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344 "2003-05-29T19:44:37Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [May 29, 2003, 7:44pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/1 "2003-05-29T19:44:37Z")

</div>

Okay, first, I’m NOT talking about music, or whatever. Let’s say I’m downloading an MP3 music clip from Amazon-just a small 30 seconds of a song to hear what it’s like. Can I get a virus from this?

The reason I ask is that my sister is trying to claim now that one can get a virus from downloading an MP3 or WAV file from an internet link. I say no, because they’re not executable files. She says yes, because, and I quote, “All my friends say so.”

Keep in mind, she is trying to convince me to put a file sharing program on my computer (Which I REFUSE TO DO!). I have told her numerous times that even if it were not illegal, I don’t like the idea of people having access to my harddrive, or that crap taking up so much space on my computer.  
So, please, computer experts-what are the dangers of downloading sound clips from the internet?

Oh, and this is a very ANTI-FILE SHARING THREAD. PLEASE, do not try to tell me that file sharing programs are good things, or anything like that. I don’t want this thread locked. Mods, if this is out of line, I appologize, and please let me know. Thanks.

---

<div class="post-metadata">

**Author:** ![daniel801](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@daniel801](https://boards.straightdope.com/u/daniel801)\
**Post date:** [May 29, 2003, 8:01pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/2 "2003-05-29T20:01:54Z")

</div>

One can give any extension name to a file, so yes.

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [May 29, 2003, 8:08pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/3 "2003-05-29T20:08:47Z")

</div>

> [@](#):
>
> \*Originally posted by daniel801 \*  
> \*\*One can give any extension name to a file, so yes. \*\*

No, that’s flat wrong. Well, ok, someone could rename an .exe with an .mp3 extension, but what’s going to happen when you double-click it is thaqt the OS will try to run whatever MP3 player that filetype is associated to, and it will fail because the format is incorrect. But the virus will not execute and cannot do any damage.

Do, however, be aware of files with a bogus “extension” as part of the filename, as in _bogusfile.mp3.exe_. If you have your computer set to hide extensions of registered file types, you will see _bogusfile.mp3_. Double-clicking that _will_ execute the file.

---

<div class="post-metadata">

**Author:** ![World\_Eater](https://avatars.discourse-cdn.com/v4/letter/w/f04885/32.png) [@World\_Eater](https://boards.straightdope.com/u/World_Eater)\
**Post date:** [May 29, 2003, 8:11pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/4 "2003-05-29T20:11:26Z")

</div>

But unless it has an .exe extension it won’t run, so no.

---

<div class="post-metadata">

**Author:** ![World\_Eater](https://avatars.discourse-cdn.com/v4/letter/w/f04885/32.png) [@World\_Eater](https://boards.straightdope.com/u/World_Eater)\
**Post date:** [May 29, 2003, 8:14pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/5 "2003-05-29T20:14:20Z")

</div>

As you all may guess I was replying to **Dan**.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [May 29, 2003, 8:17pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/6 "2003-05-29T20:17:09Z")

</div>

I don’t think my setup hides the extension, but how can I know for sure and change that if it does?

Thanks. I don’t know where my sister comes up with this crap.

---

<div class="post-metadata">

**Author:** ![SeanDuggan](https://avatars.discourse-cdn.com/v4/letter/s/258eb7/32.png) [@SeanDuggan](https://boards.straightdope.com/u/SeanDuggan)\
**Post date:** [May 29, 2003, 8:20pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/7 "2003-05-29T20:20:09Z")

</div>

Check this out: [http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-072.asp](http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-072.asp)

Basically a buffer overrun is convincing the computer to overwrite memory with a file. My impression of it is that yes, it is possible, but it’s not extremely likely. I found out about it by checking the details of all those Windows Updates that Microsoft tries to convince you to install. Darn Windows XP…

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [May 29, 2003, 8:22pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/8 "2003-05-29T20:22:14Z")

</div>

What OS are you using? If it’s a Windows OS, just open up a folder–My Documents is convenient–and click Tools \> Folder Options \> View tab. Scroll down the list and look for “Hide extensions of registered file types” and uncheck it. This is for XP, and IIRC Win 98 and up all work about the same way.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [May 29, 2003, 8:25pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/9 "2003-05-29T20:25:58Z")

</div>

Windows ME

My computer always asks before downloading a file, FWIW, and most of the files I’ve downloaded come in zip files.

---

<div class="post-metadata">

**Author:** ![Mort\_Furd](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@Mort\_Furd](https://boards.straightdope.com/u/Mort_Furd)\
**Post date:** [May 29, 2003, 8:26pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/10 "2003-05-29T20:26:30Z")

</div>

Bad news. Your sister is right.  
Some MP3 players on computers have bugs that can be exploited to transport a virus. It amounts to improperly formatting a piece of the file and causing the MP3 player to crash in such a way as to execute code embedded in the MP3 file. That code can then write out an executable file (whose code was also embedded in the MP3) and do other nastiness on your computer.

WinAMP had such a problem some time ago, which they fixed. There may be others out there with similar problems. The virus has to be targeted at your player, and won’t cause problems (except for maybe not playing) in other players.

---

<div class="post-metadata">

**Author:** ![Eats\_Crayons](https://avatars.discourse-cdn.com/v4/letter/e/278dde/32.png) [@Eats\_Crayons](https://boards.straightdope.com/u/Eats_Crayons)\
**Post date:** [May 29, 2003, 9:05pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/11 "2003-05-29T21:05:56Z")

</div>

Okay, now I have a question, just to clarify:

**Mort** if that’s the case, and the nasty stuff is in the file, then does it make any difference at all if you “download” the MP3 vs. “file share” it as per the OP?

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [May 29, 2003, 9:16pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/12 "2003-05-29T21:16:58Z")

</div>

No, but you’re far more likely to encounter such a corrupted file on a P2P network than downloading it from a legit site.

---

<div class="post-metadata">

**Author:** ![World\_Eater](https://avatars.discourse-cdn.com/v4/letter/w/f04885/32.png) [@World\_Eater](https://boards.straightdope.com/u/World_Eater)\
**Post date:** [May 29, 2003, 9:24pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/13 "2003-05-29T21:24:14Z")

</div>

I’ve not heard of any nasty virus or trojan infecting a computer in that manner. It’s possible, and I’m sure someone has managed to crash a computer or 2, but I’ve heard nothing else malicious.

---

<div class="post-metadata">

**Author:** ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)\
**Post date:** [May 29, 2003, 10:01pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/14 "2003-05-29T22:01:45Z")

</div>

You could on the Mac, which doesn’t require extensions at all and will ignore them in assessing the function of a file if it has a file type and/or creator that instructs it differently. I could take Microsoft Word (the application), rename it “RiteOfSpring\_01.mp3”, and double-click it, and still get Word. So I could do the same with a virus.

If we only had a virus, I mean.

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [May 29, 2003, 11:11pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/15 "2003-05-29T23:11:19Z")

</div>

> [@](#):
>
> \*Originally posted by Q.E.D. \*  
> \*\*No, but you’re far more likely to encounter such a corrupted file on a P2P network than downloading it from a legit site. \*\*

Well, that’s a point in my favor-Sis is trying to convince me that you’re more likely to download a virus when you download an MP3 from a website than on a program like KaZaa or whatever other crap she wants to put on my computer.

---

<div class="post-metadata">

**Author:** ![Cleophus](https://avatars.discourse-cdn.com/v4/letter/c/a88e57/32.png) [@Cleophus](https://boards.straightdope.com/u/Cleophus)\
**Post date:** [May 29, 2003, 11:42pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/16 "2003-05-29T23:42:05Z")

</div>

A buffer overflow that specifically targets a certain application, like the one Mort Furd mentioned, is the only way I can think of for a non-executable (that is, a file that really is non-executable, like an MP3, and not an executable masquerading as another file type) to infect the computer. Even then, it’s still not an executable, the hijacked player app does all the work. It doesn’t seem such an attack has been observed in the wild, though.

BTW, is your sister seriously stating downloading a prevew from Amazon brings a greater risk of getting a virus than downloading from Kazaa?

---

<div class="post-metadata">

**Author:** ![Guinastasia](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guinastasia/32/5751_2.png) [@Guinastasia](https://boards.straightdope.com/u/Guinastasia)\
**Post date:** [May 29, 2003, 11:49pm UTC](https://boards.straightdope.com/t/can-one-download-a-virus-from-an-mp3-or-wav-file/178344/17 "2003-05-29T23:49:21Z")

</div>

She didn’t say preview from Amazon-she said “downloading an MP3 from a website link as opposed to a Kazaa like program” is more dangerous.

I just used that as an example of a legitimate place to download an MP3-I do NOT want this thread closed because someone started giving me advice on downloading illegal stuff!

Basically, I do NOT want a program like a P2P on my computer-even if it WERE legal, the idea of someone being able to download off of my computer…I dunno, it doesn’t sound too secure to me.
